Containers, Cloud & DevOps
Containers, orchestration, deployment, networking, storage, security, autoscaling and the infrastructure patterns behind modern cloud-native applications.
Containers are one of the clearest examples of how operating-system concepts, software architecture and infrastructure engineering converge.
They make applications easier to package and reproduce, but running a container is only the beginning. Once applications consist of many containers distributed across multiple machines, new questions appear around scheduling, networking, persistence, security, scaling and failure recovery.
What exactly is isolated inside a container? Why is a container lighter than a virtual machine? How should a container image be built and secured? What happens when a container fails? How can hundreds of containers be deployed, updated and scaled without managing each one manually?
This section combines two complementary perspectives: understanding containers themselves through Docker, and understanding how containerized workloads can be orchestrated at scale through Kubernetes.
Topics in This Section
Containers · OCI · Docker · Container Images · Dockerfiles · Registries · Docker Compose · Container Networking · Persistent Volumes · Container Security · Kubernetes · Pods · ReplicaSets · Deployments · Services · Ingress · Autoscaling · Self-Healing · ConfigMaps · Secrets · RBAC · Service Mesh · Stateful Workloads · Persistent Storage · Network Policies · Policy & Governance · Multicluster Deployment · Cloud-Native Applications
Docker Deep Dive
Nigel Poulton
5th Edition — Packt Publishing
Level
Foundation → Intermediate
Best for
Understanding container fundamentals, Docker architecture and the practical lifecycle of containerized applications.
Docker Deep Dive is the book I use to understand what happens before orchestration begins.
It moves from the fundamental difference between containers and virtual machines to Docker Engine internals, images, application containerization, networking, persistent storage and security.
I find this particularly useful because it connects the simple developer experience of running a container with the operating-system mechanisms and standards underneath it.
What I Use It For
- understanding containers versus virtual machines;
- the Open Container Initiative and container standards;
- Docker Engine architecture;
- containerd and runc;
- container images and layers;
- registries, tags and digests;
- Dockerfiles;
- multi-stage builds;
- multi-architecture images;
- Docker Compose;
- container networking;
- overlay networks;
- persistent volumes;
- container isolation and security;
- namespaces and control groups;
- capabilities and seccomp;
- image vulnerability scanning.
Chapters Worth Reading
Container Foundations
Chapter 1 — Containers from 30,000 Feet
Why containers emerged, how they differ from virtual machines and where they fit in modern infrastructure.
Chapter 2 — Docker and Container-Related Standards and Projects
Docker’s place in the wider container ecosystem and the standards that allow container runtimes and images to interoperate.
Docker Architecture
Chapter 5 — The Docker Engine
The internal components behind the Docker runtime.
- Docker Engine;
- Open Container Initiative;
- containerd;
- runc;
- container lifecycle;
- Linux implementation.
Images & Containers
Chapter 6 — Working with Images
Container images, layers, registries, tagging, digests and multi-architecture images.
- image layers;
- registries;
- tags and digests;
- multi-architecture images;
- Docker Scout vulnerability scanning.
Chapter 7 — Working with Containers
The practical container lifecycle and the relationship between images and running containers.
- containers versus VMs;
- starting and stopping containers;
- process inspection;
- debugging;
- restart policies and basic self-healing.
Containerizing Applications
Chapter 8 — Containerizing an App
Moving an application into a reproducible container image.
- Dockerfiles;
- single-container applications;
- multi-stage builds;
- BuildKit;
- Buildx;
- multi-architecture builds;
- container-image best practices.
Multi-Container Applications
Chapter 9 — Multi-Container Apps with Compose
Defining and running applications composed of multiple cooperating containers.
- Compose files;
- application services;
- multi-container deployment;
- application lifecycle management.
Container Orchestration
Chapter 12 — Docker Swarm
A compact introduction to Docker’s native orchestration system.
I mainly use this chapter to understand orchestration concepts in a simpler environment before moving to Kubernetes: clusters, distributed application deployment and replicated services.
Networking
Chapter 13 — Docker Networking
Container networking on a single Docker host.
- bridge networks;
- container connectivity;
- port mappings;
- external access.
Chapter 14 — Docker Overlay Networking
Networking across multiple hosts and the abstractions used to connect distributed containers.
Persistent Data
Chapter 15 — Volumes and Persistent Data
Why container filesystems should generally be treated as ephemeral and how persistent state can be separated from container lifecycle.
Container Security
Chapter 16 — Docker Security
The Linux and Docker mechanisms used to isolate and protect containers.
- kernel namespaces;
- control groups;
- Linux capabilities;
- Mandatory Access Control;
- seccomp;
- image vulnerability scanning;
- image signing;
- Docker Secrets.
My Suggested Learning Path
Understand Containers
Chapters 1–2
Understand the Runtime
Chapter 5
Images & Containers
Chapters 6–7
Build Applications
Chapters 8–9
Networking
Chapters 13–14
Persistence
Chapter 15
Security
Chapter 16
Kubernetes: Up and Running
Brendan Burns, Joe Beda, Kelsey Hightower & Lachlan Evenson
3rd Edition — O’Reilly Media
Level
Intermediate → Advanced
Best for
Understanding container orchestration, declarative infrastructure, scaling, self-healing and production Kubernetes workloads.
Kubernetes: Up and Running begins where Docker alone stops being enough.
Running one container is simple. Running hundreds of containers across multiple machines while keeping the desired number of replicas available, routing traffic, managing configuration, performing rolling updates and recovering from failures is a fundamentally different problem.
The book introduces Kubernetes as a declarative system: rather than manually managing individual containers, we describe the state we want and allow controllers to continuously work toward maintaining that state.
What I Use It For
- cloud-native application principles;
- container orchestration;
- Kubernetes architecture;
- Pods;
- health checks;
- resource requests and limits;
- labels and selectors;
- service discovery;
- load balancing and Ingress;
- ReplicaSets;
- autoscaling;
- Deployments and rolling updates;
- DaemonSets and Jobs;
- ConfigMaps and Secrets;
- RBAC;
- service meshes;
- persistent storage;
- StatefulSets;
- security contexts;
- Network Policies;
- policy and governance;
- multicluster architectures.
Chapters Worth Reading
Cloud-Native Foundations
Chapter 1 — Introduction
The architectural principles behind Kubernetes and cloud-native systems.
- immutability;
- declarative configuration;
- self-healing;
- decoupling;
- scaling applications and teams;
- infrastructure abstraction.
Chapter 2 — Creating and Running Containers
A bridge between container fundamentals and Kubernetes, including image building, registries, image security and container runtimes.
Kubernetes Foundations
Chapter 3 — Deploying a Kubernetes Cluster
Cluster creation, managed Kubernetes services and the main Kubernetes components.
Chapter 4 — Common kubectl Commands
Working with Kubernetes objects, namespaces, contexts and debugging commands.
Pods & Health Management
Chapter 5 — Pods
The fundamental scheduling unit in Kubernetes.
- Pod manifests;
- logs and command execution;
- liveness probes;
- readiness probes;
- startup probes;
- resource requests;
- resource limits;
- volumes.
Labels, Discovery & Networking
Chapter 6 — Labels and Annotations
Metadata and selectors used to organise and connect Kubernetes resources.
Chapter 7 — Service Discovery
Services, DNS, Cluster IPs and mechanisms for routing traffic toward changing sets of Pods.
Chapter 8 — HTTP Load Balancing with Ingress
Routing external HTTP traffic into applications running inside the cluster.
Replication, Scaling & Deployment
Chapter 9 — ReplicaSets
Reconciliation loops, desired replica counts and horizontal application scaling.
- declarative scaling;
- ReplicaSets;
- autoscaling;
- reconciliation.
Chapter 10 — Deployments
Managing application versions and updates.
- rolling updates;
- Recreate strategy;
- deployment history;
- controlled rollout;
- rollback concepts.
Specialized Workloads
Chapter 11 — DaemonSets
Running one workload instance on selected cluster nodes.
Chapter 12 — Jobs
One-shot tasks, parallel jobs, work queues and CronJobs.
Configuration & Secrets
Chapter 13 — ConfigMaps and Secrets
Separating application configuration and sensitive information from container images.
Identity & Authorization
Chapter 14 — Role-Based Access Control for Kubernetes
Users, roles, RoleBindings and ClusterRoles used to control access to Kubernetes resources.
Service Mesh
Chapter 15 — Service Meshes
Infrastructure for managing service-to-service communication.
- mutual TLS;
- authentication;
- traffic shaping;
- observability;
- service-mesh trade-offs.
Persistent & Stateful Workloads
Chapter 16 — Integrating Storage Solutions and Kubernetes
Persistent storage and the additional challenges introduced by stateful applications.
- Persistent Volumes;
- dynamic volume provisioning;
- StatefulSets;
- reliable singletons;
- databases in Kubernetes.
Extending Kubernetes
Chapter 17 — Extending Kubernetes
Custom Resources and Operators used to extend the Kubernetes control model to application-specific resources.
Application Security
Chapter 19 — Securing Applications in Kubernetes
Security controls applied to containerized workloads.
- SecurityContext;
- Pod Security Standards;
- service accounts;
- RBAC;
- RuntimeClass;
- Network Policies;
- image security;
- security benchmarks.
Policy & Governance
Chapter 20 — Policy and Governance for Kubernetes Clusters
Enforcing organisational policies through admission controls and Open Policy Agent-based approaches.
Multicluster & Application Delivery
Chapter 21 — Multicluster Application Deployments
Architectural approaches for distributing applications across multiple Kubernetes clusters and regions.
Chapter 22 — Organizing Your Application
Structuring Kubernetes configuration for development, testing and production.
- source-control organisation;
- release progression;
- templates;
- Helm;
- multi-environment deployment;
- worldwide deployment.
My Suggested Learning Path
Cloud-Native Principles
Chapters 1–2
Kubernetes Fundamentals
Chapters 3–6
Networking & Discovery
Chapters 7–8
Scaling & Deployment
Chapters 9–12
Configuration & Access
Chapters 13–14
Service Communication & Storage
Chapters 15–16
Security & Governance
Chapters 19–20
Production Architecture
Chapters 21–22
Why I Keep Both Books
Docker Deep Dive
Container first.
- container fundamentals;
- runtime architecture;
- images;
- Dockerfiles;
- Compose;
- networking;
- volumes;
- container security.
Kubernetes: Up and Running
System first.
- orchestration;
- desired state;
- scheduling;
- replication;
- autoscaling;
- self-healing;
- service discovery;
- rolling deployment;
- cluster security;
- policy and governance.
Docker helps me understand the unit being deployed. Kubernetes helps me understand how thousands of those units can become a reliable system.
Topic → Book Map
Containers vs Virtual Machines
Docker Deep Dive: Chapters 1 and 7
Kubernetes: Up and Running: Chapters 1–2
Container Images & Registries
Docker Deep Dive: Chapters 6 and 8
Kubernetes: Up and Running: Chapter 2
Container Runtime
Docker Deep Dive: Chapter 5
Kubernetes: Up and Running: Chapter 2
Application Deployment
Docker Deep Dive: Chapters 8–9
Kubernetes: Up and Running: Chapters 9–10 and 22
Networking & Service Discovery
Docker Deep Dive: Chapters 13–14
Kubernetes: Up and Running: Chapters 7–8
Persistent Storage
Docker Deep Dive: Chapter 15
Kubernetes: Up and Running: Chapters 5 and 16
Scaling & Self-Healing
Docker Deep Dive: Chapters 7 and 12
Kubernetes: Up and Running: Chapters 5, 9 and 10
Security
Docker Deep Dive: Chapter 16
Kubernetes: Up and Running: Chapters 14, 19 and 20
How I Use These Books
I find container platforms easier to understand when I separate the problem into two layers: the container itself and the system responsible for managing containers at scale.
“Why does this application run consistently on my laptop and in production?”
That leads to container images, immutable artifacts, dependencies and reproducible builds.
“One application instance crashes. Who starts another one?”
That leads to restart policies at container level and reconciliation controllers, ReplicaSets and Deployments at Kubernetes level.
“Traffic suddenly triples. How can the application add capacity automatically?”
That leads to horizontal replication, autoscaling, resource requests, scheduling and load balancing.
“A container is destroyed. Why does the application data survive?”
That points toward separating ephemeral compute from persistent storage through volumes and persistent-volume abstractions.
Understand the container first. Then understand the control system that keeps thousands of containers in the state the application requires.
Related Areas
Containers and orchestration connect infrastructure with almost every other area in this library.
Operating Systems & Virtualization
Processes, kernel isolation, namespaces, resource management and virtual machines.
Software Architecture & Microservices
Independent deployment, service boundaries, progressive delivery and cloud-native applications.
Distributed Systems
Replication, scheduling, failure recovery, distributed state and coordination.
Computer Networks
Virtual networks, routing, load balancing, service discovery and network policies.
Cybersecurity & Cryptography
Image security, least privilege, identity, RBAC, secrets and network isolation.
Databases & Data Management
Persistent workloads, StatefulSets, distributed storage and database lifecycle management.